Description
Blind SQL injection in a service running in Snow Software license manager from version 8.0.0 up to and including 9.30.1 on Windows allows a logged in user with high privileges to inject SQL commands via the web portal.
No analysis available yet.
Remediation
Vendor Solution
Upgrade to version 9.30.2 or if running 9.27.0 apply the hotfix 9.27.1
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-44492 | Blind SQL injection in a service running in Snow Software license manager from version 8.0.0 up to and including 9.30.1 on Windows allows a logged in user with high privileges to inject SQL commands via the web portal. |
References
| Link | Providers |
|---|---|
| https://community.snowsoftware.com/s/feed/0D56M00009gUexuSAC |
|
History
Wed, 09 Oct 2024 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:snowsoftware:snow_license_manager:*:*:*:*:*:*:*:* | |
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Snow
Published:
Updated: 2024-10-09T19:13:07.827Z
Reserved: 2023-07-24T13:51:33.771Z
Link: CVE-2023-3864
Updated: 2024-08-02T07:08:50.529Z
Status : Modified
Published: 2023-08-11T12:15:09.293
Modified: 2024-11-21T08:18:15.003
Link: CVE-2023-3864
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD